Cloud Storage Company Dropbox Warns Users of Unauthorised Account Access via Lenovo ID Flaw
Dropbox has alerted some users that their accounts were accessed by an unauthorized party due to a vulnerability in Lenovo’s email verification process. This allowed attackers to register fake Lenovo IDs and subsequently access the associated Dropbox account without needing the login password. The incident highlights the importance of robust authentication mechanisms and the need for service providers to promptly address potential security risks.
The issue was related to Lenovo Identity Provider Services, which allows users to log in to their Dropbox accounts using verified Lenovo IDs. An investigation by Dropbox found that an attacker exploited a flaw in Lenovo’s email verification process, enabling them to register a fake Lenovo ID using the victim’s email address. This allowed them to access the Dropbox account without needing the login password.
Dropbox uses an identity-linking process that trusts Lenovo’s assertion of control over the email address, effectively bypassing the need for an additional confirmation step via the existing Dropbox login method. The company has since changed its behavior to require users to enter their Dropbox account password when attempting to log in using a Lenovo ID.
The incident occurred between August 4 and 21, with approximately 5,000 accounts accessed by the attackers. According to reports, some users had their content viewed or downloaded without their consent. The investigation is ongoing, but Lenovo has stated that only non-Lenovo customers were affected by the issue.
This incident serves as a reminder of the importance of robust authentication and verification processes in preventing unauthorised access to sensitive accounts. Service providers must ensure they have adequate measures in place to detect and mitigate potential security risks, particularly when integrating third-party services into their infrastructure.
For users, this incident underscores the need for vigilance when using cloud storage services. If you receive notifications about suspicious activity on your Dropbox account, change your password immediately and consider activating two-factor authentication (2FA) as an additional precautionary measure. By staying informed and taking proactive steps to secure your accounts, you can better protect yourself against potential security threats.
Source: Bleeping Computer — 2026-09-02